CVE-2026-48204Disclosure(apache / camel)

MEDIUMCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch apache camel systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Improper Input Validation, Improper Access Control vulnerability in Apache Camel in Camel Mongodb Gridfs component. The camel-mongodb-gridfs producer selects the GridFS operation to perform from the gridfs.operation Exchange header when the endpoint's operation parameter is not set - which is the default. The control-header constants (GridFsConstants.GRIDFS_OPERATION, GRIDFS_OBJECT_ID, GRIDFS_METADATA, GRIDFS_CHUNKSIZE, GRIDFS_FILE_ID_PRODUCED) were the plain strings gridfs.operation, gridfs.objectid, gridfs.metadata, gridfs.chunksize and gridfs.fileid. Because these names do not start with the Camel / camel prefix, HttpHeaderFilterStrategy - which blocks only the Camel header namespace on the HTTP boundary - let them pass from an inbound HTTP request straight into the Exchange. In a route that bridges an HTTP consumer (for example platform-http) into a mongodb-gridfs: producer with no explicit operation, any HTTP client could therefore set the gridfs.operation header to override the route's intended operation - switching, for example, a file upload to remove (deleting a file identified by the attacker-supplied gridfs.objectid), listAll (enumerating every file in the bucket) or findOne (reading a file) - and supply a gridfs.metadata value that is parsed as a MongoDB document, enabling NoSQL operator injection. No credentials are required when the bridging consumer is unauthenticated. This issue affects Apache Camel: from 4.0.0 before 4.14.8, from 4.15.0 before 4.18.3, from 4.19.0 before 4.21.0. Users are recommended to upgrade to version 4.21.0, which fixes the issue. If users are on the 4.14.x LTS releases stream, then they are suggested to upgrade to 4.14.8. If users are on the 4.18.x releases stream, then they are suggested to upgrade to 4.18.3. After upgrading, routes that drive GridFS operations or metadata via the raw header names must use CamelGridFsOperation / CamelGridFsObjectId / CamelGridFsMetadata / CamelGridFsChunkSize / CamelGridFsFileId instead of the gridfs.* names. For deployments that cannot upgrade immediately, set an explicit operation on the mongodb-gridfs: endpoint so the operation is not taken from a header, and strip the gridfs.* headers from any untrusted ingress before the producer.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-284

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • camel

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-07-20)
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
camel

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-07-07: 1Mentions · 2026-07-16: 1Mentions · 2026-07-18: 1Mentions · 2026-07-20: 2PoC Mentioned / Linked · 2026-07-20: 1Exploit Tool / Code · 2026-07-20: 1Patch / Workaround · 2026-07-07: 1Technical Details · 2026-07-07: 1Technical Details · 2026-07-18: 1Technical Details · 2026-07-20: 207-0707-1607-1807-20
Signal classification3 categories
Disclosure
360.0%
Patch
120.0%
PoC
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-07-071
Patch1
2026-07-161
Disclosure1
2026-07-181
Disclosure1
2026-07-202
Disclosure1PoC1
Full discourse5 posts
  • dbugs@ptdbugs
    PoC

    A PoC/exploit has been discovered for vulnerability CVE-2026-48204 PT ID: PT-2026-55900 Vendor: Apache Software Foundation Product: Apache Camel Description: Improper Input Validation, Improper Access Control vulnerability in Apache Camel in Camel Mongodb Gridfs component. The camel-mongodb-gridfs producer selects the GridFS operation to perform from the gridfs.operation Exchange header when the endpoint's operation parameter is not set - which is the default. The control-header constants (GridFsConstants.GRIDFS_OPERATION, GRIDFS_OBJECT_ID, GRIDFS_METADATA, GRIDFS_CHUNKSIZE, GRIDFS_FILE_ID_PRODUCED) were the plain strings gridfs.operation, gridfs.objectid, gridfs.metadata, gridfs.chunksize and gridfs.fileid. Because these names do not start with the Camel / camel prefix, HttpHeaderFilterStrategy - which blocks only the Camel header namespace on the HTTP boundary - let them pass from an inbound HTTP request straight into the Exchange. In a route that bridges an HTTP consumer (for example platform-http) into a mongodb-gridfs: producer with no explicit operation, any HTTP client could therefore set the gridfs.operation header to override the route's intended operation - switching, for example, a file upload to remove (deleting a file identified by the attacker-supplied gridfs.objectid), listAll (enumerating every file in the bucket) or findOne (reading a file) - and supply a gridfs.metadata value that is parsed as a MongoDB document, enabling NoSQL operator injection. No credentials are required when the bridging consumer is unauthenticated. This issue affects Apache Camel: from 4.0.0 before 4.14.8, from 4.15.0 before 4.18.3, from 4.19.0 before 4.21.0. References: • https://dbugs.ptsecurity.com/vulnerability/PT-2026-55900 • https://github.com/oscerd/cve-2026-48204 #dbugs_vuln

    Post summary

    A proof‑of‑concept exploit for CVE‑2026‑48204 in Apache Camel’s MongoDB GridFS component has been released, detailing the vulnerability’s technical mechanics.

    000711.1K
    3.4K followersView on X
  • The NoSQL Nerd@NoSQLNerd
    Disclosure

    Apache Camel CVE-2026-48204 lets unauthenticated attackers hijack MongoDB GridFS operations via HTTP headers. NoSQL injection, arbitrary file read/delete. Affects Camel 4.0-4.21.0. https://dbugs.ptsecurity.com/vulnerability/PT-2026-55900

    Post summary

    The post announces CVE‑2026‑48204 in Apache Camel, detailing a NoSQL injection that allows unauthenticated users to hijack MongoDB GridFS operations for arbitrary read/delete, with preliminary information and a link to the advisory.

    0000038
    16 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    Disclosure

    【緊急】CVE-2026-48204 Apache Camel 4.0.0 から 4.14.8 未満、4.15.0 から 4.18.3 未満、4.19.0 から 4.21.0 未満に深刻な脆弱性|即時対応が必要 https://www.cybernote.click/2026/07/11/cve-2026-48204-apache-camel-400-4148-4150-4183-4190-4210/ #IT #Security #cybersecurity

    Post summary

    The notice announces a serious vulnerability (CVE-2026-48204) affecting multiple Apache Camel versions and calls for immediate remediation.

    0000044
    208 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    Disclosure

    【緊急】CVE-2026-48204 Apache Camel 4.0.0 から 4.14.8 未満、4.15.0 から 4.18.3 未満、4.19.0 から 4.21.0 未満に深刻な脆弱性|即時対応が必要 https://www.cybernote.click/2026/07/11/cve-2026-48204-apache-camel-400-4148-4150-4183-4190-4210/ #IT #Security #cybersecurity

    Post summary

    The message announces a critical vulnerability (CVE-2026-48204) affecting multiple Apache Camel versions and urges immediate action.

    0000051
    207 followersView on X
  • SecAlerts@SecAlertsCo
    Patch

    🐪 Apache Camel (MongoDB GridFS) CVSS 9.8: HTTP clients can bypass header filters via unprefix'd gridfs.* headers to hijack GridFS operations. No auth needed. CVE-2026-48204 — patch now. #ApacheCamel #infosec https://secalerts.co/vulnerability/CVE-2026-48204?utm_campaign=x https://t.co/gYZZRbyj1h

    Post summary

    Apache Camel’s GridFS module has a critical CVE (CVE-2026-48204) that allows header bypass and hijacking without authentication; a patch has been released.

    0000093
    852 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachecamel---

Explore more